IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Ref 0180066743.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\new[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\RegAsm.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
ISO-8859 text
dropped
malicious
C:\Users\user\AppData\Roaming\win33.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$Ref 0180066743.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1717583E.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\17662F27.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6A2B8E08.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\707074AB.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\81C8EEFC.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\86ABDEF1.png
PNG image data, 399 x 605, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\87A50956.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9D956669.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CEC1BA6A.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E476B363.png
PNG image data, 399 x 605, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E8E50EB0.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EF6436D2.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FD088ACD.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FFD606D5.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\user\AppData\Local\Temp\RegAsm.exe
C:\Users\user\AppData\Local\Temp\RegAsm.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
wekeepworking.sytes.net
malicious
http://198.12.127.155/new.exe
198.12.127.155
malicious
wekeepworking12.sytes.net
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.day.com/dam/1.0
unknown
clean

Domains

Name
IP
Malicious
wekeepworking.sytes.net
79.134.225.90
malicious
wekeepworking12.sytes.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
79.134.225.90
wekeepworking.sytes.net
Switzerland
malicious
198.12.127.155
unknown
United States
malicious

Registry

Path
Value
Malicious
C:\Users\Public\vbc.exe
Shell
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
nz6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EEE36
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1h6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3E19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4A2A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3E19
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
There are 52 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3526000
unkown
page read and write
malicious
32B1000
unkown
page read and write
malicious
DF2000
unkown image
page execute read
malicious
DF2000
unkown image
page execute read
malicious
2A21000
unkown
page read and write
malicious
3B49000
unkown
page read and write
malicious
22B1000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
DE0000
unkown
page read and write
malicious
3395000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
3F6000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
2365000
unkown
page read and write
clean
DDE000
unkown
page read and write | page guard
clean
330000
unkown
page read and write
clean
C00000
unkown
page read and write
clean
25F4000
heap private
page read and write
clean
366000
heap private
page read and write
clean
51CF000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
AB9000
heap private
page read and write
clean
660000
unkown
page read and write
clean
DA0000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
25EC000
unkown
page read and write
clean
4B5E000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
2367000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
302F000
unkown
page read and write
clean
E06000
unkown
page read and write
clean
C10000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
CB0000
unkown
page read and write
clean
442E000
unkown
page read and write
clean
380000
heap default
page read and write
clean
2D0A000
unkown
page read and write
clean
AD6000
heap private
page read and write
clean
3E0000
unkown
page readonly
clean
5B6D000
unkown
page read and write
clean
1FD000
unkown
page read and write
clean
3DD6000
unkown
page read and write
clean
2340000
unkown
page read and write
clean
194000
unkown
page read and write
clean
90000
unkown
page readonly
clean
A40000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
180000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
22FC000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
3CE000
unkown image
page readonly
clean
660000
unkown
page read and write
clean
235F000
unkown
page read and write
clean
4A10000
unkown
page read and write
clean
2344000
unkown
page read and write
clean
88B000
unkown
page read and write
clean
1D0000
unkown
page execute and read and write
clean
DA0000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
E30000
unkown
page read and write
clean
660000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
110000
unkown
page read and write
clean
2470000
unkown
page read and write
clean
CD0000
unkown
page execute and read and write
clean
3DB6000
unkown
page read and write
clean
C10000
unkown
page read and write
clean
42C0000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
4950000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
3CF6000
unkown
page read and write
clean
85B000
heap default
page read and write
clean
ECE000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
5A6000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
3F0000
unkown
page read and write
clean
C14000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
1F6000
unkown
page read and write
clean
370000
unkown
page read and write
clean
49D000
heap default
page read and write
clean
1C2000
unkown
page read and write
clean
E08000
unkown
page read and write
clean
E10000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
340000
unkown
page read and write
clean
548F000
unkown
page read and write
clean
E80000
unkown
page read and write
clean
C30000
heap private
page execute and read and write
clean
C0000
unkown
page read and write
clean
7D4000
heap default
page read and write
clean
E10000
unkown
page read and write
clean
E20000
unkown
page read and write
clean
DB0000
unkown
page read and write
clean
D64000
heap private
page read and write
clean
430000
unkown
page read and write
clean
5F7E000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
87E000
heap default
page read and write
clean
234C000
unkown
page read and write
clean
889000
unkown
page read and write
clean
3C2000
unkown image
page execute read
clean
590000
unkown
page read and write
clean
400000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
2AD1000
unkown
page read and write
clean
4320000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
410000
unkown
page read and write
clean
220000
unkown
page read and write
clean
91D000
unkown
page read and write
clean
6E9000
unkown
page read and write
clean
47E0000
unkown
page read and write
clean
61EC000
unkown
page read and write
clean
2B38000
unkown
page read and write
clean
5DAE000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
310000
heap private
page read and write
clean
2470000
unkown
page read and write
clean
400000
unkown
page read and write
clean
2348000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
668000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
440000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
5D8000
unkown
page read and write
clean
E40000
heap private
page execute and read and write
clean
19D000
unkown
page execute and read and write
clean
8B0000
unkown
page readonly
clean
1FA000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
AAE000
unkown
page read and write
clean
42D0000
unkown
page read and write
clean
3DF6000
unkown
page read and write
clean
5960000
heap private
page read and write
clean
420000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
886000
unkown
page read and write
clean
234E000
unkown
page read and write
clean
3E36000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
227000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
5419000
unkown
page read and write
clean
49F0000
unkown
page read and write
clean
210000
heap private
page read and write
clean
5428000
unkown
page read and write
clean
4990000
unkown
page read and write
clean
3D76000
unkown
page read and write
clean
3CB6000
unkown
page read and write
clean
1C6000
unkown
page execute and read and write
clean
DDF000
unkown
page read and write
clean
3A69000
unkown
page read and write
clean
E10000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
400000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
410000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
1E0000
unkown
page read and write
clean
5A5000
unkown
page read and write
clean
4476000
unkown
page read and write
clean
3A0000
unkown
page readonly
clean
5419000
unkown
page read and write
clean
457000
heap default
page read and write
clean
5C00000
heap private
page read and write
clean
6F0000
unkown
page read and write
clean
4E40000
unkown
page write copy
clean
B0000
unkown image
page readonly
clean
CC0000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
2470000
unkown
page read and write
clean
2470000
unkown
page read and write
clean
603000
heap default
page read and write
clean
DB0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
4C4E000
unkown
page read and write
clean
360000
heap private
page read and write
clean
6C0000
unkown
page read and write
clean
420000
unkown
page read and write
clean
1DB000
unkown
page execute and read and write
clean
886000
unkown
page read and write
clean
430000
unkown
page read and write
clean
236B000
unkown
page read and write
clean
420000
unkown
page read and write
clean
7ED000
heap default
page read and write
clean
50EF000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
110000
unkown
page readonly
clean
4A8E000
unkown
page read and write
clean
2470000
unkown
page read and write
clean
550000
unkown
page readonly
clean
42F0000
unkown
page read and write
clean
577C000
unkown
page read and write
clean
2D78000
unkown
page read and write
clean
49E0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
DC0000
unkown
page read and write
clean
4ACC000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
684E000
unkown
page read and write
clean
660000
unkown
page read and write
clean
88B000
unkown
page read and write
clean
BFD000
unkown
page read and write
clean
AF8000
unkown
page read and write
clean
370000
unkown
page read and write
clean
DF0000
unkown image
page readonly
clean
E10000
unkown
page read and write
clean
53FF000
unkown
page read and write
clean
474000
heap default
page read and write
clean
E15000
unkown
page read and write
clean
D60000
heap private
page read and write
clean
1F0000
unkown
page readonly
clean
49A0000
heap private
page execute and read and write
clean
630E000
unkown
page read and write
clean
20000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
80000
unkown
page readonly
clean
E00000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
420000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
1F9000
unkown
page read and write
clean
4430000
unkown
page readonly
clean
3A0000
unkown
page read and write
clean
410000
unkown
page read and write
clean
4B60000
unkown
page readonly
clean
3F0000
unkown
page read and write
clean
3A89000
unkown
page read and write
clean
3CE000
unkown image
page readonly
clean
66C000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
4980000
unkown
page read and write
clean
5590000
heap private
page read and write
clean
8D0000
unkown
page read and write
clean
410000
unkown
page read and write
clean
410000
unkown
page execute and read and write
clean
170000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
5418000
unkown
page read and write
clean
660000
unkown
page read and write
clean
350000
unkown
page read and write
clean
5416000
unkown
page read and write
clean
12D000
unkown
page execute and read and write
clean
558E000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
400000
unkown
page read and write
clean
E07000
unkown
page read and write
clean
192000
unkown
page read and write
clean
889000
unkown
page read and write
clean
5408000
unkown
page read and write
clean
A6F000
unkown
page read and write
clean
C00000
unkown
page read and write
clean
4960000
unkown
page read and write
clean
718000
unkown
page read and write
clean
3F8000
unkown
page read and write
clean
DD0000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
A9E000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
E30000
unkown
page read and write
clean
4970000
unkown
page read and write
clean
886000
unkown
page read and write
clean
A30000
unkown
page readonly
clean
7E8000
heap default
page read and write
clean
432E000
unkown
page read and write
clean
317000
heap private
page read and write
clean
2363000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
C00000
unkown
page read and write
clean
C10000
unkown
page read and write
clean
81D000
heap default
page read and write
clean
88A000
unkown
page read and write
clean
3CE000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
42B0000
unkown
page read and write
clean
4940000
unkown
page read and write
clean
886000
unkown
page read and write
clean
5404000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
C00000
unkown
page read and write
clean
335000
heap private
page read and write
clean
4FEE000
unkown
page read and write
clean
DA0000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
886000
unkown
page read and write
clean
50F0000
unkown
page readonly
clean
2460000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
D50000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
6310000
unkown
page write copy
clean
400000
unkown
page read and write
clean
C09000
unkown
page read and write
clean
3C96000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
430000
unkown
page execute and read and write
clean
4F20000
unkown
page readonly
clean
426000
unkown
page read and write
clean
5406000
unkown
page read and write
clean
6F3000
unkown
page read and write
clean
370000
unkown
page read and write
clean
200000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
1F0000
unkown
page read and write
clean
56AF000
unkown
page read and write
clean
B90000
unkown
page readonly
clean
8D0000
unkown
page read and write
clean
888000
unkown
page read and write
clean
C00000
unkown
page read and write
clean
C0D000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
E10000
unkown
page read and write
clean
2332000
unkown
page read and write
clean
7B0000
heap default
page read and write
clean
6AE000
unkown
page read and write
clean
3B0000
unkown
page write copy
clean
897000
unkown
page read and write
clean
888000
unkown
page read and write
clean
59EC000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
4810000
unkown
page read and write
clean
390000
heap private
page read and write
clean
889000
unkown
page read and write
clean
E06000
unkown
page read and write
clean
96E000
unkown
page read and write
clean
DF0000
unkown image
page readonly
clean
200000
unkown
page read and write
clean
613000
heap default
page read and write
clean
4C50000
unkown
page readonly
clean
51CE000
unkown
page read and write | page guard
clean
3F0000
unkown
page read and write
clean
88A000
unkown
page read and write
clean
3CE000
unkown image
page readonly
clean
C6E000
unkown
page read and write
clean
C70000
heap private
page execute and read and write
clean
5419000
unkown
page read and write
clean
3C2000
unkown image
page execute read
clean
5404000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
590000
unkown
page read and write
clean
2612000
heap private
page read and write
clean
5428000
unkown
page read and write
clean
AB0000
heap private
page read and write
clean
1A0000
heap private
page read and write
clean
6E0000
unkown
page read and write
clean
CB0000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
370000
unkown
page read and write
clean
88A000
unkown
page read and write
clean
D50000
unkown
page read and write
clean
4920000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
193000
unkown
page execute and read and write
clean
400000
unkown
page execute and read and write
clean
C20000
unkown
page read and write
clean
33E000
unkown
page read and write
clean
88B000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
7B7000
heap default
page read and write
clean
400000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
124000
unkown
page read and write
clean
220000
unkown
page read and write
clean
4700000
unkown
page readonly
clean
1BD000
unkown
page execute and read and write
clean
DE0000
unkown
page read and write
clean
400000
unkown
page read and write
clean
400000
unkown
page read and write
clean
886000
unkown
page read and write
clean
220000
unkown
page read and write
clean
123000
unkown
page execute and read and write
clean
325000
unkown
page read and write
clean
58FE000
unkown
page read and write
clean
5413000
unkown
page read and write
clean
3D96000
unkown
page read and write
clean
5B5000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
6F2000
unkown
page read and write
clean
2346000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
380000
unkown
page read and write
clean
5D4D000
unkown
page read and write
clean
A0000
unkown
page read and write
clean
4B0000
heap default
page read and write
clean
5419000
unkown
page read and write
clean
88B000
unkown
page read and write
clean
440000
unkown
page read and write
clean
660000
unkown
page read and write
clean
440000
unkown
page read and write
clean
20000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
1D2000
unkown
page read and write
clean
330000
unkown
page read and write
clean
50AE000
unkown
page read and write
clean
660000
unkown
page read and write
clean
420000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
E12000
unkown
page read and write
clean
53D0000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
E20000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
420000
unkown
page read and write
clean
5C5000
unkown
page read and write
clean
D82000
heap private
page read and write
clean
6B0000
unkown
page read and write
clean
DB0000
unkown
page read and write
clean
2342000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
E96000
unkown image
page readonly
clean
42B0000
unkown
page read and write
clean
2470000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
590000
unkown
page read and write
clean
49A000
heap default
page read and write
clean
D50000
unkown
page read and write
clean
4930000
unkown
page read and write
clean
553D000
unkown
page read and write
clean
4AD000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
220000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
2630000
unkown
page readonly
clean
521E000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
3C2000
unkown image
page execute read
clean
E96000
unkown image
page readonly
clean
8D0000
unkown
page read and write
clean
920000
heap private
page read and write
clean
370000
unkown
page read and write
clean
200000
unkown
page read and write
clean
55FF000
unkown
page read and write
clean
16B000
unkown
page read and write
clean
420000
unkown
page read and write
clean
588D000
unkown
page read and write
clean
590000
unkown
page read and write
clean
DF0000
unkown image
page readonly
clean
CAE000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
5DEE000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
C00000
unkown
page read and write
clean
660000
unkown
page read and write
clean
AE0000
unkown
page readonly
clean
5B0000
unkown
page read and write
clean
410000
unkown
page read and write
clean
4310000
unkown
page read and write
clean
4800000
unkown
page read and write
clean
410000
unkown
page read and write
clean
200000
unkown
page read and write
clean
88B000
unkown
page read and write
clean
AA0000
heap private
page execute and read and write
clean
420000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
E16000
unkown
page read and write
clean
6E6000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
187000
unkown
page execute and read and write
clean
65CD000
unkown
page read and write
clean
235D000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
700000
heap private
page execute and read and write
clean
DC4000
unkown
page read and write
clean
590000
unkown
page read and write
clean
3CD6000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
2361000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
2E5000
unkown
page read and write
clean
350000
unkown
page execute and read and write
clean
491F000
unkown
page read and write
clean
443000
unkown
page read and write
clean
10A000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
5419000
unkown
page read and write
clean
6160000
heap private
page read and write
clean
6E0000
unkown
page read and write
clean
2369000
unkown
page read and write
clean
340000
unkown
page read and write
clean
436000
unkown
page read and write
clean
1C0000
unkown
page read and write
clean
DD0000
unkown
page read and write
clean
3C2000
unkown image
page execute read
clean
234A000
unkown
page read and write
clean
17D000
unkown
page execute and read and write
clean
3A21000
unkown
page read and write
clean
E10000
unkown
page read and write
clean
1060000
unkown
page readonly
clean
400000
unkown
page execute and read and write
clean
5C0000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
370000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
22E3000
unkown
page read and write
clean
6F6000
unkown
page read and write
clean
2480000
unkown
page read and write
clean
5E0000
heap default
page read and write
clean
6F0000
unkown
page read and write
clean
5407000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
6D0000
unkown
page readonly
clean
5B0000
unkown
page read and write
clean
70E000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
C10000
unkown
page read and write
clean
DE0000
unkown
page read and write
clean
42E0000
unkown
page read and write
clean
1F6000
unkown
page read and write
clean
237C000
unkown
page read and write
clean
25F0000
heap private
page read and write
clean
8D0000
unkown
page read and write
clean
220000
unkown
page read and write
clean
DC0000
unkown
page read and write
clean
E20000
unkown
page read and write
clean
1CA000
unkown
page execute and read and write
clean
3F6000
unkown
page read and write
clean
5428000
unkown
page read and write
clean
5419000
unkown
page read and write
clean
4A00000
unkown
page execute and read and write
clean
5C0000
unkown
page read and write
clean
203000
unkown
page read and write
clean
42C0000
unkown
page execute and read and write
clean
197000
unkown
page execute and read and write
clean
450000
heap default
page read and write
clean
590000
unkown
page read and write
clean
420000
unkown
page read and write
clean
697E000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
258F000
unkown
page read and write
clean
590000
unkown
page read and write
clean
2D0E000
unkown
page read and write
clean
1D7000
unkown
page execute and read and write
clean
3A5000
unkown
page read and write
clean
666000
unkown
page read and write
clean
440000
unkown
page read and write
clean
E05000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
C2D000
unkown
page read and write
clean
E10000
unkown
page read and write
clean
490000
heap default
page read and write
clean
420000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
B0000
unkown
page read and write
clean
2FE9000
unkown
page read and write
clean
There are 564 hidden memdumps, click here to show them.